This page was machine-translated and may differ from the original. View original
Conducted practical exercises on evidence collection and attack chain tracing based on MAESTRO WiSDOM
Maestro Forensic, a digital forensics specialist, held a practical training seminar to strengthen intrusion analysis capabilities in the macOS environment. The Mac support features of the AI-based integrated forensic platform MAESTRO WiSDOM were covered alongside actual ransomware response cases, systematically introducing incident response procedures in multi-operating system environments.Maestro Forensics announced on the 2nd that it held the 'MAESTRO WiSDOM Mac Forensics Seminar' at the Insec Security Seoul Doksan Education Center in Doksan-dong, Seoul on the 1st.
This seminar introduced the procedures for evidence collection, deleted data recovery, and digital trace analysis in the macOS environment, and was conducted in a hands-on manner for the participants.
MAESTRO WiSDOM is an AI-based forensic platform that performs integrated analysis across various operating systems, including Windows, macOS, Linux, and mobile.
It is equipped with 'Forensic Accelerator' technology that supports evidence identification and analysis more than five times faster than foreign solutions, and is capable of tracking LotL (Living off the Land), Fileless, and EDR Killer types of attacks.
The company explained that it can identify the attack chain by correlating more than 1,000 digital artifacts.
At this seminar, 'Forensic Crane,' an evidence collection tool dedicated to the macOS Live environment, was also introduced.
It was announced that it automatically collects over 250 macOS live artifacts and supports both live and power-off imaging on Apple Silicon chips (M1–M5) and the latest macOS 26 (Tahoe).
△MD5 △SHA-1 △SHA-256 It ensures evidence integrity through SHA-512 hash value calculation and provides various output formats such as ZIP, AFF4, Sparse Image, and MAEFDB.
At the seminar, a case study on the response to Qilin Ransomware, which Maestro Forensics disclosed last February, was also shared.
The company stated that in the breach incident involving a combination of LotL and fileless techniques, they performed an initial analysis of a 2TB disk within four hours, recovered deleted event logs, and identified the cause within three days.
The practical session covered a multi-operating-operating environment by analyzing Windows file systems, registry, and event logs, as well as handling Linux EXT and XFS file systems.
"Recent security breaches often combine ransomware, LotL, and fileless attacks, making it difficult to identify the cause with existing security solutions alone," said Kim Jong-kwang, CEO of Maestro Forensic. "We plan to continue operating regular training courses so that field analysts can utilize Maestro Wisdom more quickly and accurately in the process of responding to actual incidents."
The training schedule and registration can be found on the Insec Security website (www.insec.co.kr).
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.















